Home
MEDIUM: 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NMEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
8.3.0 (semver) before 8.3.3
affected
8.2.0 (semver) before 8.2.10
affected
8.0.0 (semver) before 8.0.24
affected
7.0.0 (semver) before 7.0.35
affected
Description
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Problem types
CWE-532 Insertion of sensitive information into log file
Product status
8.3.0 (semver) before 8.3.3
8.2.0 (semver) before 8.2.10
8.0.0 (semver) before 8.0.24
7.0.0 (semver) before 7.0.35
References
jira.mongodb.org/browse/SERVER-123370